What's New

New updates and improvements to Jumpstart Pro

Ruby 4.0.7, Pay 12, and Receipts 3

Update

We've upgraded to Ruby 4.0.7, Bundler 4.0.21, Pay 12, Receipts 3, and ActsAsTenant 2.

Receipts 3 generates PDFs in pure Ruby without Prawn and includes the Inter font, so you no longer need to configure fonts. Pay 12 wraps Stripe errors in its own error classes. See UPGRADE.md for details.

Confirm email address changes

New

Changing your email address now sends a confirmation link to the new address, and the change only takes effect once you click it. Links expire after an hour and requests are rate limited.

Once confirmed, the old address gets a security notice and all other sessions are signed out. No password is needed, so this works for users who signed up with OAuth too.

Better mobile styles out of the box

Improvement
  • Form inputs use a 16px font on small screens so iOS Safari doesn't zoom on focus.
  • Wide tables and code no longer cause the page to scroll sideways.
  • Modals fit the screen with proper gutters and scroll containment.
  • Cards, headings, and the sidebar layout are tighter on phones.

Scoped API tokens

New

API tokens can now carry scoped permissions like accounts:read. You define scopes and their actions in config/initializers/api_tokens.rb, so they can match your own resources, for example "blog_posts" => %w[read publish archive].

Existing and new tokens are granted every permission, so current behavior is unchanged.

Native Google and Apple sign in for Hotwire Native

New

Google blocks OAuth inside embedded web views, so "Sign in with Google" couldn't work in Hotwire Native apps. Jumpstart Pro now adds native Google and Apple sign in endpoints along with bridge components. The app gets an ID token from the platform and Jumpstart verifies it and starts a session.

Just like on the web, a social login can't take over an existing account with the same email.

The Android hamburger menu also now appears on every tab root.

Rails 8 authentication replaces Devise

New

Jumpstart Pro now uses Rails' built-in authentication instead of Devise. Pretender and Pundit are also gone, replaced by an Impersonation concern and simple role guards. Authentication now works the way Rails generates it: plain code in your app that's easy to read and change.

What still works

  • Existing passwords. Devise's bcrypt digests still verify, so nobody needs to reset.
  • Two-factor authentication, OAuth providers, and impersonation.
  • Old Devise sign in, sign up, and password URLs redirect to the new pages.

What your users will notice

  • Everyone is signed out once when you deploy.
  • Password reset links sent before the deploy stop working.
  • The "Remember me" checkbox is gone because sessions are always persistent.

Breaking changes

Authentication is now required by default. Use allow_unauthenticated_access to make actions public. Helpers have been renamed too, for example authenticate_user! is now require_authentication and user_signed_in? is now authenticated?. UPGRADE.md has step-by-step instructions and a script that does the renames for you.

Updated Render.com deploys

Improvement

The render.yaml blueprint now uses Render's Projects and Environments, the current Postgres plan names, and runs Puma in single mode. We also fixed the Sidekiq worker config.

Dark mode and error page fixes

Fix
  • Dark mode no longer flashes white before the page paints.
  • Checkboxes and input backgrounds look correct in dark mode.
  • Every HTTP error status now renders a proper error page instead of a blank body.
  • Canonical URLs can no longer be manipulated through query parameters.

Admin improvements

Improvement
  • Impersonate users directly from the Madmin users list.
  • System admins keep full access while impersonating, even when the user doesn't have a subscription.
  • The admin column on users has been renamed to staff to avoid confusion with account admins. This is a breaking change, so check UPGRADE.md for details.

Stop repeat free trials

Improvement

If a customer has already used a free trial and checks out with Stripe again, Jumpstart now requires a payment method up front, so they can't start another free trial without one.

The current subscription is also cached per request, which speeds up pages that check it repeatedly.

Billing role

New

You can now give account members a Billing role, which lets them manage subscriptions, payment methods, and receipts without full admin access. Members without it no longer see billing links.

Account roles are now defined in an initializer, so adding your own roles is easier.

Rails 8.1.3.1

Update

We've upgraded to Rails 8.1.3.1. Everything is tested and passing, so we recommend upgrading.

Canonical URLs by default

Improvement

Every page now includes a canonical URL tag for better SEO. It always uses https, keeps only meaningful query params, and ignores page=1. It works together with the meta tags helpers we added last year.

RSS feed for announcements

New

Announcements now have an RSS feed so your users can follow your changelog in their favorite reader. You can subscribe to this one too!

Admins can also preview scheduled announcements before they go live, and announcements without a publish date are labeled as drafts.

Ruby 4.0.6

New

We've upgraded to the latest Ruby 4.0.6 which is a maintenance release that includes several bugfixes. Everything is tested and passed, so it's ready to use.

Embed videos and iframes in Lexxy

Improvement

Lexxy can now embed iframes from allowed providers, including bunny.net, Bluesky, and Spotify's updated embed endpoint. Video embeds also no longer autoplay.

Simpler team sign up and API fixes

Improvement

Team sign up now creates the account automatically using the name you enter, which removes an extra step.

The API now returns proper 404 responses for invalid account IDs and only exposes the routes it actually supports.

We've also upgraded to image_processing 2.0 and now use ruby-vips explicitly, so make sure libvips is installed wherever you deploy.

Feedback Request Email Feature

New

When a customer cancels their subscription to your app, Jumpstart Pro now automatically sends them a simple feedback request email after the cancellation and asks a single open-ended question — what made you cancel? Replies go straight to your support address, so the feedback lands directly in your inbox without any extra tooling.

A few details worth knowing: The "from" name and reply-to address pull from your Jumpstart configuration support email address, so no extra setup is needed beyond what you've already configured.

Ruby 4.0.5

New

Jumpstart now runs on the latest Ruby version, 4.0.5. See the Ruby 4.0.5 release notes to learn more.

Ruby 4.0.4

Update

We've upgraded to Ruby 4.0.4, a maintenance release with several bugfixes. Everything is tested and passing, so it's ready to use.